TA555TA555

Also known as: TA555

Known aliases
1

Profile

Beginning in May 2018, Proofpoint researchers observed a previously undocumented downloader dubbed AdvisorsBot appearing in malicious email campaigns. The campaigns appear to primarily target hotels, restaurants, and telecommunications, and are distributed by an actor we track as TA555. To date, we have observed AdvisorsBot used as a first-stage payload, loading a fingerprinting module that, as with Marap, is presumably used to identify targets of interest to further infect with additional modules or payloads. AdvisorsBot is under active development and we have also observed another version of the malware completely rewritten in PowerShell and .NET.

Aliases· 1

TA555

Compliance frameworks testing this (incoming)4

TypeTargetConfidenceTier
ComplianceControlowasp_api_top10-api10100%live
ComplianceControlowasp_top10-a01100%live
ComplianceControlcra-art14100%live
ComplianceControltiber_eu-generic100%live

References

  1. https://www.thaicert.or.th/downloads/files/Threat_Group_Cards_v2.0.pdf

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Actor
TA558
Actor
TA570
Actor
TA554
Actor
TA578
Actor
TA571
Actor
TA530
Sourced from MISP-Galaxy Threat Actor cluster. Curated by Adam Lundqvist, Founder at SQUR.